Description
Missing authorization checks in the Backend Routing of TYPO3 CMS versions 9.0.0‑9.5.54, 10.0.0‑10.4.53, 11.0.0‑11.5.47, 12.0.0‑12.4.36, and 13.0.0‑13.4.17 allow backend users to directly invoke AJAX backend routes without having access to the corresponding backend modules.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2019-2615 Vulnerability (CVE-2019-2615)
WordPress Plugin Video Gallery-Best WordPress YouTube Gallery Multiple Vulnerabilities (1.7.6)
WordPress Plugin WordPress Calls to Action Multiple Vulnerabilities (2.3.7)
phpMyAdmin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2016-9862)
WordPress Plugin Wholesale Market for WooCommerce Arbitrary File Download (1.0.7)